I had instances where many of my forwaders filled up disk partition to go full.
How can I disable all logging? Ofcourse I have selected "store local copy" as no.
Thanks, Gurus!
You can adjust Splunk local logging configurations in $SPLUNK_HOME/etc/log.cfg